2018 CVE Vulnerabilities

17,817 CVEs published in 2018.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2018-12475MEDIUM5.4A Externally Controlled Reference to a Resource in Another Sphere vulnerability in obs-service-download_files of openSUS...
CVE-2018-1985MEDIUM4.4IBM Trusteer Rapport/Apex 3.6.1908.22 contains an unused legacy driver which could allow a user with administrator privi...
CVE-2018-21256MEDIUM4.3An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for...
CVE-2018-21252MEDIUM4.3An issue was discovered in Mattermost Server before 5.2, 5.1.1, 5.0.3, and 4.10.3. Attackers could use multiple e-mail a...
CVE-2018-21265MEDIUM5.3An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRe...
CVE-2018-21261MEDIUM4.3An issue was discovered in Mattermost Server before 4.8.1, 4.7.4, and 4.6.3. An e-mail invite accidentally included the ...
CVE-2018-21259MEDIUM5.3An issue was discovered in Mattermost Server before 4.10.1, 4.9.4, and 4.8.2. It allows attackers to cause a denial of s...
CVE-2018-21257MEDIUM5.3An issue was discovered in Mattermost Server before 5.1. It allows attackers to bypass intended access restrictions (for...
CVE-2018-21255MEDIUM4.3An issue was discovered in Mattermost Server before 5.1. Non-members of a channel could use the Channel PATCH API to mod...
CVE-2018-21254MEDIUM4.3An issue was discovered in Mattermost Server before 5.1. An attacker can bypass intended access control (for direct-mess...
CVE-2018-21253MEDIUM4.3An issue was discovered in Mattermost Server before 5.1, 5.0.2, and 4.10.2. An attacker could use the invite_people slas...
CVE-2018-21250MEDIUM6.5An issue was discovered in Mattermost Server before 5.2.2, 5.1.2, and 4.10.4. It allows remote attackers to cause a deni...
CVE-2018-16848MEDIUM6.5A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a...
CVE-2018-21243MEDIUM6.5An issue was discovered in Foxit PhantomPDF before 8.3.6. It has COM object mishandling when Microsoft Word is used.
CVE-2018-21239MEDIUM5.3An issue was discovered in Foxit Reader and PhantomPDF before 9.2. It allows NTLM credential theft via a GoToE or GoToR ...
CVE-2018-21237MEDIUM5.3An issue was discovered in Foxit PhantomPDF before 8.3.7. It allows NTLM credential theft via a GoToE or GoToR action.
CVE-2018-18625MEDIUM6.1Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an...
CVE-2018-18624MEDIUM6.1Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an ...
CVE-2018-18623MEDIUM6.1Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen. NOTE: this issue exists because of an incomplete fix for ...
CVE-2018-8956MEDIUM5.3ntpd in ntp 4.2.8p10, 4.2.8p11, 4.2.8p12 and 4.2.8p13 allow remote attackers to prevent a broadcast client from synchron...
CVE-2018-21233MEDIUM6.5TensorFlow before 1.7.0 has an integer overflow that causes an out-of-bounds read, possibly causing disclosure of the co...
CVE-2018-21232MEDIUM5.5re2c before 2.0 has uncontrolled recursion that causes stack consumption in find_fixed_tags.
CVE-2018-21225MEDIUM6.8Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7000 before 1.0.1.60, ...
CVE-2018-21209MEDIUM4.8Certain NETGEAR devices are affected by reflected XSS. This affects JNR1010v2 before 1.1.0.46, JR6150 before 1.0.1.10, J...
CVE-2018-21201MEDIUM6.8Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects D6100 befor...

Check if your code is affected by 2018 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now